Insight · 19 September 2026

Nearest Neighbor Attack: your network does not stop at the wall

Wireless coverage plot over a building drawing; the coloured signal fields extend beyond the building outline marked in red
A wireless coverage plot over a floor plan. The red line is the building envelope. The access points sit inside; the signal does not stop at that line.

In 2018 the Russian military intelligence service GRU came to The Hague. Back when it still had to. Four intelligence officers in a rented Citroën in a car park beside the OPCW, Wi-Fi interception equipment hidden under a coat. The Dutch military intelligence service MIVD disrupted the close-access operation.

Four years later the car was redundant. In February 2022 Volexity found successful GRU logins to the enterprise Wi-Fi of an organisation in Washington. The credentials, obtained through password spraying, were of no use for breaking into the company through its remote-working provision or other internet-facing services, because MFA was enabled. For the Wi-Fi, a valid username and password were enough. The remarkable part: the actor was thousands of kilometres away.

The GRU compromised organisations in surrounding buildings until it found a system that was connected both by cable and wirelessly, and logged in to the target’s Wi-Fi from there. The logs showed that the connection ran through access points near a meeting room on the street side of the building. The attack is known as the Nearest Neighbor Attack, because that is precisely what it is: a close-access operation run from your neighbours.

The vulnerability was not in the device or the password policy, but in the electromagnetic emission and in the assumption that this signal posed no risk outside the secured zone. The target’s network reached beyond the walls of the building, and the company across the street unwittingly became a link in the attack chain.

In the Netherlands this is no longer merely a technical detail. The Dutch Cybersecurity Act entered into force on 15 August and more than eight thousand organisations fall under it. The duty of care requires them to map their cyber risks and take appropriate measures. That includes the above, and unknown or unmanaged access points, guest networks, 4G routers and anything with a camera and a microphone. Oversight of this is a board responsibility.

A case like Nearest Neighbor makes one thing clear: you cannot properly assess security measures without knowing the actual perimeter. Yet many organisations have limited visibility of the wireless landscape around their building: which known and unknown signals are present there and what vulnerabilities that creates. Let alone around the rooms where confidential conversations take place. If you have your network pen-tested, why not your most important rooms as well?

Sources

  1. Volexity. “The Nearest Neighbor Attack: How A Russian APT Weaponized Nearby Wi-Fi Networks for Covert Access.” November 2024. The primary source for this account: detection on 4 February 2022, the password spraying, MFA on the internet-facing service but not on the Wi-Fi, the chain through neighbouring organisations and the access points near the street-side meeting room.
  2. Netherlands Ministry of Defence. “Russian cyber operation disrupted.” October 2018. Confirms that the MIVD disrupted a GRU cyber operation against the OPCW on 13 April 2018, with the assistance of the AIVD and UK counterparts.
  3. Electrospaces. “The GRU close access operation against the OPCW in perspective.” October 2018. Analysis of the material published by the MIVD: the four officers, the rented Citroën and the equipment in the boot.
  4. Government of the Netherlands. “Cyberbeveiligingswet en Wet weerbaarheid kritieke entiteiten vanaf 15 augustus 2026 van kracht.” July 2026. Source for the date of entry into force, the figure of more than eight thousand organisations and the board’s ultimate responsibility.
  5. NCSC. “Zorgplicht.” What the duty of care asks of organisations in concrete terms.

Read more about our electronic security surveys and TSCM sweeps.

Written by · Published